Manual ResistTel IP2 / IP152
Page 183
ExResistTel IP2 / IP154
HTTPS
Basic authentication, only
Local users and remote Kerberos users.
As a consequence you have to use HTTPS if you want to login with a Kerberos user
account.
4.3.2.1.2.5
Authorization
Tickets issued by an own Kerberos server contain some information whether the user
is an administrator or a viewer. When it comes to cross-realm authentication with a
Windows domain the own Kerberos server can map between Windows group
memberships and administrator rights.
4.3.2.1.2.6
The PBX as a Kerberos Server
Special PBX also provides for Kerberos authentication for its users without additional
configuration:
The
System Name
of the PBX is the name of the realm.
Users with both a password and rights defined can be used for delegated
authentication.
The
Name
of the user object in the PBX can be used as the user name for
authentication.
Users with the right
Full PBX Administration
are administrators in the Kerberos
realm. Users with other rights are viewers.
LDAP replication also works with the Kerberos information.
There is a special user called
_KADMIN_
that can be used to add devices to
the realm but not to login to the user interface.
4.3.2.1.3
Configuration
4.3.2.1.3.1
Setting up the Kerberos Server
The Kerberos server of a PBX is configured using the PBX/Security page.
Configuration of the stand-alone Kerberos server is done using the General/Kerberos
page.
Summary of Contents for ExResistTel IP2/IP154
Page 43: ...Manual ResistTel IP2 IP152 Page 43 ExResistTel IP2 IP154 Figure 9 Set View ...
Page 386: ...Page 386 Manual ResistTel IP2 IP152 ExResistTel IP2 IP154 ...
Page 387: ...Manual ResistTel IP2 IP152 Page 387 ExResistTel IP2 IP154 ...
Page 390: ...Page 390 Manual ResistTel IP2 IP152 ExResistTel IP2 IP154 ...